Impact
The vulnerability is an incorrect authorization in the WebProtect component of Google Chrome. Prior to version 152.0.7977.65, a remote attacker can design an HTML page that, when opened by a user, forces the browser to bypass system access restrictions that normally prevent non‑privileged web content from accessing protected APIs. This results in an authorization bypass that could allow the attacker to execute code or retrieve sensitive data from the user’s system.
Affected Systems
Affected systems are installations of Google Chrome older than 152.0.7977.65 on any platform where the WebProtect feature is enabled. The vulnerability is classified under CWE-863.
Risk and Exploitability
The issue has a CVSS score of 4.3 and an EPSS score of < 1%, indicating low severity and a very low but nonzero likelihood of exploitation. It is not listed in the CISA KEV catalog, suggesting no publicly known active exploitation. The vulnerability requires only a crafted HTML page that can be delivered remotely, so the attack vector is remote. A patch is recommended before a deployed exploit emerges.
OpenCVE Enrichment
Debian DLA
Debian DSA